AI is the first technology in years that staff will adopt whether or not you have decided to. The risk is rarely the tool itself — it is that Copilot can instantly surface a decade of files nobody has looked at, including the ones with permissions that were never quite right. We are a security-first managed services provider, so we do this in that order: assess what your data would expose, close what it finds, then deploy under proper control. Afterwards, governance is part of your managed service rather than a project that ended.
Assess first
AI enabled only after the data is governed
What is included
- SharePoint data exposure review
- Knowledge structure review
- AI governance review
- Deployment readiness summary
- Recommended improvement plan
- Delivered in days, not months
What changes
You find out before your staff do
A data exposure assessment before AI is enabled, not after someone surfaces the wrong document.
Every question is logged
A full audit trail of what was asked, what was accessed and what was done with it.
Actions need a person
Anything that changes a record or sends a message is presented for approval. AI proposes; people decide.
Method
How Keystone works
Assess
We review your data exposure first – SharePoint permissions, sharing links, structure. AI never meets your data before you know what it would find.
Secure
Close what the assessment found. Permissions tightened, legacy links retired, governance controls in place.
Connect
Your systems are connected one at a time, each deliberately scoped. CRM, service desk, finance – nothing by default.
Ask
Your team asks questions in Microsoft Teams and gets real answers from live systems. No new application, no training programme.
Govern
Every query logged, actions gated behind human approval, access reviewed as part of your managed service.
What the assessment looks at
Permissions that were never quite right
Copilot surfaces what a person already has access to. The problem is that access in most Microsoft 365 tenants has accumulated for years — inherited permissions, sharing links set to anyone, sites nobody owns. None of it mattered while finding a file required knowing where it was.
Whether your content can produce a good answer
AI reflects the structure it is given. Where the same document exists in four versions across three sites, the answers are confidently wrong, which is worse than no answer at all.
What is governing it
Tenant configuration, admin policy and audit settings decide what AI can reach and what is recorded when it does. This is the part that a client questionnaire or an auditor will eventually ask about.
Then a plan, in days
The output is a written summary of what was found, ranked by risk, with what to fix before enabling anything. If your data is already in reasonable shape it says so. Keystone is the next step once it is.
What it costs
Managed IT and security is priced per user, per month, with Microsoft/Google platform management charged as one flat monthly band on top. The full numbers are published rather than hidden behind a quote.
